1068
you are viewing a single comment's thread
view the rest of the comments
[-] AllHailTheSheep@sh.itjust.works 17 points 1 week ago

I hate sites that make me constantly change passwords. it's been shown time and time again that making users change passwords often decreases security by a pretty large factor, and yet a lot of sites still do it

[-] MrsDoyle@sh.itjust.works 11 points 1 week ago

Our workplace did that. You had to change every month and you weren't allowed to just add a digit. It meant that people started writing their passwords on post-its stuck to the monitor.

Mind you, back in the 90s your password was the same as your username. It was very handy, because if someone went home leaving a document locked, you could just log in and unlock it. Our first "proper" IT professional was horrified.

[-] brbposting@sh.itjust.works 7 points 1 week ago

Interesting, stopped seeing this a while back. Forced change after the inevitable hack though of course

[-] Object@sh.itjust.works 7 points 1 week ago

Could be because OWASP now actively recommends against periodic password changes.

Ensure credential rotation when a password leak occurs, at the time of compromise identification or when authenticator technology changes. Avoid requiring periodic password changes; instead, encourage users to pick strong passwords and enable Multifactor Authentication Cheat Sheet (MFA). According to NIST guidelines, verifiers should not mandate arbitrary password changes (e.g., periodically).

this post was submitted on 27 Jul 2025
1068 points (98.9% liked)

Greentext

6887 readers
1651 users here now

This is a place to share greentexts and witness the confounding life of Anon. If you're new to the Greentext community, think of it as a sort of zoo with Anon as the main attraction.

Be warned:

If you find yourself getting angry (or god forbid, agreeing) with something Anon has said, you might be doing it wrong.

founded 2 years ago
MODERATORS